Record summary

CVE-2025-11368 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template methods. This makes it possible for unauthenticated attackers to retrieve admin curriculum HTML, quiz questions with correct answers, course materials, and other sensitive educational content via the REST API endpoint granted they can supply valid numeric IDs.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 31, 2026 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 21, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

Browse thimpress / LearnPress – WordPress LMS Plugin for Create and Sell Online Courses

Default status: unaffected

CVE ListThrough 4.2.9.4affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMLearnPress < 4.3.0 - Arbitrary Callback Execution to Information ExposureCVSS 5.3

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, and including, 4.2.9.4. This is due to missing capability checks in the REST endpoint /wp-json/lp/v1/load_content_via_ajax which allows arbitrary callback execution of admin-only template methods. This makes it possible for unauthenticated attackers to retrieve admin curriculum HTML, quiz questions with correct answers, course materials, and other sensitive educational content via the REST API endpoint granted they can supply valid numeric IDs.

Impact

Unauthenticated attackers can access sensitive admin curriculum, quiz answers, and course materials, compromising educational content confidentiality.

Remediation

Update to the latest version beyond 4.2.9.4.

WeaknessesCWE-200
Authorspussycat0x
Template tagscvecve2025wordpresswp-scanwp-pluginlearnpressvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Shodan: http.html:"/wp-content/plugins/learnpress/"
FOFA: body="/wp-content/plugins/learnpress/"

Source: ProjectDiscovery

References

4